Name : East Star Installer
Aliases : No Aliases
Type/Size : File/8340
Clone : No Clones
Symptoms : No Symptoms
Discovered : ?
Way to infect: No infection
Rating : Less dangerous
Kickstarts : 1.2/1.3
Damage : Installs the East Star Virus im memory.
Manifestation: -
Removal : Delete File
Comments : The EastStar Installer was linked together
with NComm. This Link was created by using
Hunklab. If you are now starting the file
it first installs the EastStar virus in
memory.
Name : Electro Vision
Aliases : No Aliases
Type/Size : Boot/1024
Original : Forbip
Symptoms : No Symptoms
Discovered : 10-09-93
Way to infect: Boot infection
Rating : Less Dangerous
Kickstarts : 1.2/1.3
Damage : Overwrites boot.
Removal : Install boot.
Comments : The Electro Vision Virus is another FORBIP-Clone.
So please look there for further information.
Name : Eleni 3
Aliases : No Aliases
Type/Size : Boot/1024
Clones : No Clones
Symptoms : No Symptoms
Discovered : 23-04-94
Way to infect: Boot Infection
Rating : Dangerous
Kickstarts : 2.X/3.X
Damage : Damages LoadFiles
Removal : Install Boot
Comments : If you`re starting the Eleni 3 virus it allocates
20000 byte Chip-memory as long as there isn`t any Chip
memory anymore. The the virus copies itself into the
last available chip-area.
Then the virus patches the DoIO()-Vector to infect
other disks. If you`re now inserting a disk the virus
checks if the disk is already infected by loading the
bootblock at address $70000. If the disk is already
infected the virus subs 1 from a special address,
which is on some AMIGAS the Clock-Address (A2000, I
think). But all this will be done if there was a
bootblock READ-Access. If a WRITE-Access is requested,
the virus patches the LoadSeg()-Vector from the
"dos.library".
This LoadSeg-patch will do the following:
If a file will be loaded the virus checks for the
Clock Address. If this address reached the value 1 the
virus insert a new name for LoadSeg, "ELENI!". In the
CLI you will get this error:
`Unknown command: "ELENI!"`
If the Clock-Address reached 0 the virus loads the
actual file into address $70000 und some bytes in this
file will be changed. You will see a GURU.
NOTE from Alex:
All in all the virus is very LAME-Coded. Please guys!
Don`t pollute our beloved AMIGA with such shit!
Name : Eleni 3 Dropper
Aliases : MessAngel Killer
Type/Size : Trojan/7100 unpacked, PP-Packed 1808 byte
Clones : No Clones
Symptoms : No Symptoms
Discovered : 20-09-94
Way to infect: No Infection
Rating : Less Dangerous
Kickstarts : 2.X/3.X
Damage : Installs the ELENI3 virus
Manifestation: Pretends to be a Viruskiller!
Removal : Delete File immediately.
Comments : -> For description please see "MessAngel Killer"
Name : ELENI VIRUS
Aliases : Gremlin, FMFOJ
Type/Size : Boot/1024
Clones : No Clones
Symptoms : No Symptoms
Discovered : 10-04-94
Way to infect: Boot infection
Rating : Less Dangerous
Kickstarts : 2.0 & higher
Damage : Overwrites boot, creates new c/Mount on disk.
Removal : Install boot, Delete files c/Mount & c/d.
Comments : If you are booting with an infected disk the
virus copies itself to the adress $FE000 or
$7F400. After that it changes the CoolCpature
Vector to stay resident. Furthermore it
patches the DoIO()-Vector and the KickChkSum()-
vector from the exec.library to infect other
disks.
But now it comes:
Imagine you are now booting with your HD. Now the
virus creates two new files called
c/Mount = 208 bytes (read ELENIV2.2_inst, too!)
and
c/D = 1024 bytes
The Datafile c/D is the virus itself.
The executeable file c/Mount is the virusinstaller.
If you are now starting the file c/Mount the program
does the follwing:
1) Opens the file c/D (Virus)
2) Loads it into a adress
3) starts it & returns.
To remove the virus you must delete the Mount-fake
and the virusfile c/D. AND! Don`t forget to install
your disks.
In the Bootblock you can read:
"FMFOJ XJSVT V2.2"
Decrypted with "sub.b #1,(a0)+":
(Routine not in BB)
"ELENI WIRUS V2.2"
^
The programmer was urely a LAMER
No Textoutput-routine was found in the virus.
ATTENTION: A FAKE X-COPY 8.5 VERSION IS GOING AROUND
WHICH INSTALLS THIS DEVIL. For further information
read about the X-Copy 8.5 trojan.
NOTE: Why must people write such SHIT! ohhh gooood.
Name : Eleni V2.2_inst
Aliases : Fake-Mount
Type/Size : Trojan/208
Clones : No Clones
Symptoms : No Symptoms
Discovered : 30-07-92
Way to infect: No infection
Rating : Dangerous
Kickstarts : 1.2/1.3/2.0
Damage : Installs the Eleni V2.2 virus.
Removal : Delete File.
Comments : This file installs the Eleni V2.2 virus.
Please read Eleni V2.2 for further information.
Name : Elien
Aliases : No Aliases
Type/Size : Trojan/596 unpacked, PP-Packed 1016 byte
Clones : No Clones
Symptoms : No Symptoms
Discovered : 06-07-94
Way to infect: No Infection
Rating : Dangerous
Kickstarts : 2.X/3.X
Damage : TRIES to cause hardware damages of HD.
Removal : Delete File immediately.
Comments : This nasty Anti-Elien trojan file is found in a file
called "elien.exe": 1016 bytes PowerPacked: 596 bytes.
unpacked.
This trojan is found at several bulletin boards
worldwide in an archive named anti_elien.lha without
ANY... doc ??? What do you think ??? strange isn't????
The Anti-Elien trojan is told to be a new kind of
anti-virus program against the Elien viruses to place
in your startup-sequence, but don't trust it....
In the Elien viruschecker trojan 0.1 you can read the
following ASCII txt:
"Elien_virus_checker v0.1 by zupa/T.L.X.
If you are starting the Elien viruschecker trojan file
the DosTrace 2.20 will give you the following system
messages in an endless loop:
" elien.exe: Writing 9 bytes to
"Workbench2.1:MeGaSUXX.TXT": OK"
.......and so on...............
If you are starting the Elien Trojan it to late to do
anything against it. The trojan creates a new file on
the "SYS:"-Device which is called "MeGaSUXX.TXT" and
writes in a loop (100000 times) the letters "aaaaaaaa"
in this file. If you`re now reseting your Amiga while
and writeing it can cause harderrors ! Be careful with
this devil ones!!
If your floppy disk or HD comes up with errors such as
checksum errors you can always use a repair program
as DiskSalv or like to repair it!
Name : Elien viruschecker
Aliases : No aliases
Type/Size : File/596
Original : Elien_virus_checker v0.1
Symptoms : No symptoms.
Discovered : 23-07-94
Way to infect: When executed
Rating : Less dangerous
Kickstarts : 1.2 and above
Removal : Delete it!
Comments : This nasty Anti-Elien trojan file is found in a file
called "elien.exe": 1016 bytes PowerPacked: 596 bytes.
unpacked.
This trojan is found at several bulletin boards
worldwide in an archive named anti_elien.lha without
ANY... doc ??? What do you think ??? strange isn't????
The Anti-Elien trojan is told to be a new kind of
anti-virus program against the Elien viruses to place
in your startup-sequence, but don't trust it....
In the Elien viruschecker trojan 0.1 file you can read
the following ASCII txt:
"Elien_virus_checker v0.1 by zupa/T.L.X.
If you are starting the Elien viruschecker trojan file
the DosTrace 2.20 will give you the following system
messages in an endless loop:
" elien.exe: Writing 9 bytes to
"Workbench2.1:MeGaSUXX.TXT": OK"
and so on...............
Within the executable you can read the following:
$VER:Elien_virus_checker v0.1 by zupa/T.L.X.
DAMAGE: Opens the file 'sys:MeGaSUXX.TXT' twice! Then
it begins to write 9 bytes endlessly to it! The
original intention was proably to "only" write 100000
times but because the programmer is lousy it never
stops!
If your floppy disk or HD comes up with errors such as
checksum errors you can always use DiskSalv to repair
it!
Name : EM-Wurm
Aliases : Anti-EuroMail-File-Virus, $a0 QuickInt Trojan
Type/Size : Trojan BBS Infiltrator
Clone : Not known clones yet
Symptoms : A little confusing, not elucidated really
Discovered : 16-07-91
Way to infect: No Spreading
Rating : Less Dangerous
Kickstarts : Preferably 2.x, but not only maybe.
Damage : Indeed dangerous for BBS equilibrists
Removal : Remove the file immediately
Comments : Usually the EM-Wurm trojan is embedded in downloaded
powerpacked programmes which contains their own
installers.
QuickInt is its real name but sometimes something's
going wrong with its work. It will then occur with
the name $a0 and this is a variable in the
environment Env:
(RAM:Env/name)
Liken:
1.SYS:> Echo > Env:a0 poooh
1.SYS:> Echo $a0
poooh
1.SYS:>
or the command GetEnv.
Anyway, the file $a0 is protected ---- -w-d in
c: and has always displaced the file QuickInt.
Therefore this one shouldn't work. But, ...
Damage All files in the entire directory concerned are
overwritten.
Nothing to salvage at all.
Manifestation When the file is executed it will start a search for
all divices or directories with names e.g.:
EM:, EuroMail:, EuroSYS: or similar to that.
When found it will overwrite the device contents
with nonsense data. Especially the search for EM: is
a bit tricky. ( Enquiries_of_Mine ... Root:EM )
The behavior of the program is not explained in all
details, yet, but when the Prefs:Env is copied to the
environment during booting of system 2.x it would
possibly be a good idea to take a look there.
Sometimes it looks like it chucks a none-writeable
character in the beginning of the StartUp-Sequence
because of an empty line when edited.
Take for example it is a LF ( LineFeed ). Nothing to
see except the empty line. Watch Your StartUp's first
calls.
More comments Something gives the conjecture that the file
originately was made to upload at a BBS. When the
System Administrator then unpacked the file on his
BBS the file would execute without his cooperation,
which means, it could download something to the
uploader, unless the System Administrator turned
the mainpower off his machine.
In this way the invisible character in the
StartUp-Sequence probably would be a CR ( Carriage
Return "^m" )
Name : Ethik
Aliases : Shit, Hackers
Type/Size : Boot/1024
Clones : No Clone
Symptoms : No Symptoms
Discovered : 25-09-91
Way to infect: Boot infection
Rating : Very Dangerous
Kickstarts : 1.2/1.3 (2.0=GURU!)
Damage : Overwrites boot.
Removal : Install boot.
Comments : -> See SHIT-Virus
Name : Euromail
Aliases : EM-Wurm, AnitEuromail
Type/Size : Trojan/3888
Clone : No Clones
Symptoms : No Symptoms
Discovered : 16-07-91
Way to infect: No infection
Rating : Dangerous
Kickstarts : 1.2/1.3/2.0
Damage : Damage Files.
Removal : Delete file.
Comments : The Euromail virus is a dangerous virus. It
only becomes active, if one of the following drawers
exists: EM, EUROMAIL, EUROSYS.
If you are starting the virus, it tries to damage
the file c:protect. After that the virus creates
a file c:$A0 and modifies the startup-sequence
with $A0, $0A. The virus starts the process
"clipboard.device". All files in the above mentioned
drawers will be damaged. Such damaged files CANNOT
be repaired.
Name : Excrement
Aliases : Probably none
Type/Size : Bootblock, 1024 bytes (two blocks, 0,1 )
Clone : Sentinel
Symptoms : Light diodes start blinking
Discovered : Not elucidated
Way to infect: Infects every none write-protected disk
Rating : Harmless
Kickstarts : 1.2, 1.3, 2.0
Damage : None
Manifestation: In the bootblock you can read: ary.EXCREMENT.-.
Removal : Reinstall the disk.
Comments : The Excrement-Virus uses the coolcapture-vector to
stay resident in memory. Further the virus uses the
DoIO()-Vector from the EXEC.library to infect other
disks. The virus copies itself always to the same
memory-adress ($7f400).
Depending of infections the POWER-LED begins to flash.
Name : Excrement Installer
Aliases : No Aliases
Type/Size : File/1180
Clone : No Clones
Symptoms : No Symptoms
Way to infect: No infection
Rating : Less dangerous
Kickstarts : 1.2/1.3
Damage : Installs the Excrement Virus
Removal : Delete File.
Comments : If you are starting the file, it installs the
Excrement virus in memory. Nothing more to say
about it.
Name : Excreminator 1
Aliases : No aliases
Clone/origin : No clone
Type/Size : Trojan bomb /2392 bytes
Symptoms : The disk drive heads starts to step ahead
Discovered : 24-02-92
Way to infect: No spreading
Rating : Very dangerous, but infect only floppy disks
Kickstarts : Infect by using 1.2, 1.3, 2.0, 3.0
Damage : Drive heads and disks, if you are very unluckey
Manifestation: Pretend to be a viruskiller
Removal : See below
Comments : The Excreminator 1 is running at Kickstart 2.04/3.0
too!! No spreading routine and no hidden vectors.
Pretends to be a viruskiller, but you should know
better.
When activated the virus will search for the name
exec.library. When not found it will copy itself to
that name.( The system exec.library is resident in
the KickRom.boot )
On your screen you get the message:
-*- Excreminator V1.0 -*- Written by 'The
Lame Trio (TLT)' in 1991 Memory Check ...
Checking BootBlock for Virus ... OK!
No Virus found!
Some copies can pop-up a requester which urges you:
remove the writeprotection
If you are starting the virus it tries to create a 4
bytes long file in the LIBS directory with the name
"exec.library". This file contains only the hexcode
5. If you are now starting the file again, ithe virus
decreases the value until it becames 0. Then the virus
tries to execute a quick-format...ALL disk drive heads
steps ahead.
The file named exec.library will exist some place on
a device. ( disk ). This file contents a counter
which will call itself recursive when the counter is
decreased to less than five. Every time it reaches
zero the drive engine(s) will be turned on. (On that
stage it is an endless loop ).
Result: (Not a Dos disk) and Display-Alert. This disks
or files CANNOT.. be repaired. Then an alert appeares
giving out this message:
ALL DRIVES FUCKED UP! LAME SUCKER !!!
Use a better Viruskiller next time! e.g.
Excreminator II HAHAHA and so on.
Then you get a reset.
Click on this gadget to see a @{" Demo " SYSTEM V-IFF:Excreminator1} of the
Excreminator 1 virus. Push left mouse button to
return.
The disk drive hardware is directly programmed. All
infected disks are overwritten by nonsens.
ADVICE:
Remove all 3 files very quick and replace the
original files again, if possible:
1. The origin virus (2392 bytes)
2. The Libs/exec.library (4 bytes)
3. The file in the startup-sequence entry called
"Excreminator" or whatever this trojan is
called.
Way to infect When activated the virus will search for the name
exec.library. When not found it will copy itself to
that name.( The system exec.library is resident in
the KickRom.boot ). It's probably not a good idea to
copy the entire diskette to a harddisk, included the
StartUp-Sequence if you get a new program.
Damage If you not remove the virus, the diskdrive possibly
can be overstrained. It's a little uncertain if it
acts in the same manner as some games where you
have to change the disk, regardless of the diskdrives
state.
Manifestation A file named exec.library will exist some place on
a device. ( disk ). This file contents a counter
which will call itself recursive when the counter is
decreased to less than five. Every time it reaches
zero the drive engine(s) will be turned on.
( On that stage it is an endless loop ).
Name : Executors
Aliases : No Aliases
Type/Size : Boot/1024
Original : Disk Herpes
Symptoms : No Symptoms
Discovered : 17-11-92
Way to infect: Boot infection
Rating : Dangerous
Kickstarts : 1.2/1.3/2.0
Damage : Overwrites boot/Overwrites Root-block.
Removal : Install boot.
Comments : The Executors Virus is another Disk Herpes clone. Only
the texts were changed. The intire surface at track 79
(the Root:) is overwritten with zeroes.
Does not need the trackdisk.device, so, probably it
can infect a harddisk too
Damage: The intire surface at track 79 (the Root:
) is overwritten with zeroes.
When the counter in some copies is incremented to 5 by
by infecting other disks the following text will be
displayed:
HI ! THE EXECUTORS ARE HERE
Some of your fucking Disks are
infected with the Virus V1
Greets are going to :
M A X O F S T A R L I G H T
Lamer....FUCK OFF!
Name : Exorcist
Aliases : Satan
Type/Size : Boot/1024
Original : Alien New Beat
Symptoms : No Symptoms
Discovered : 10-09-93
Way to infect: Boot infection
Rating : Dangerous
Kickstarts : 1.2/1.3
Damage : Overwrites boot.
Removal : Install boot.
Comments : The Exorcist Virus is another Alien New Beat Clone.
Only the texts were changed. For further informations
please look there.
Name : Express2.20
Aliases : No Aliases
Type/Size : AIBON Installer 194064 bytes. Aibon 776 bytes
Clone : No Clones
Symptoms : No Symptoms
Discovered : 16-11-90
Way to infect: No infection
Rating : very DANGEROUS !
Kickstarts : 1.2/1.3/2.0/3.0
Damage : Damage files.
Removal : Delete File.
Comments : A file which pretends to be a new mailing system for
BBS's. It is unique. Express2.20 135400 bytes packed
with lha. Unpacked 194064 bytes with an 776 bytes
executable appendage named "aibon".
When the Express 2.20 program is runned it does an
unconditional jump to the label aibon and from there
the tracking halts.
The Express 2.20a bomb you can download yourself from
several BBS's with the name:
d-aex220.lha
If you are starting the virus it tries to copy
Aibon to ":s". Then the virus modifies the startup-
sequence with the virusname. After all changings were
successful all files in "sys:" will be cut down to 42
bytes.
This files CANNOT.... be repaired. The virus checks
for "bbs:", too. If existing ALL files will be first
destroyed there.
It is very common to fabricate installers with an
executeable and a Path-generating part. From the
moment the program is installed there is no need for
the installer anymore.
The task of the Path-generating part is only to
enquire the users preferable device, then embed it in
the executable and sometimes, after that, throw
itself away.
In this case it's obviously not the concern. It
probably is a spin from a hackers workshop.
If convenient, see the file EM-Wurm, too.
ADVICE:
a) Delete s/Aibon
b) Delete Express2.20
c) Change your Startup-Sequence (!)
Name : Extreme
Aliases : No Aliases
Type/Size : Boot/1024
Clone : Zaccess 3, Primavera, Fat2
Symptoms : No Symptoms
Discovered : 14-08-91
Way to infect: Boot infection
Rating : Dangerous
Kickstarts : 1.2/1.3
Damage : Overwrites boot/Destroys Disk(s).
Removal : Install boot.
Comments : The Extreme virus uses the kick vectors to
stay resident in memory. To infect other disks
the virus uses the DoIO()-Vector from the
exec.library. When a special value reaches 0
the virus start a quickformat routine and shows
the following alert:
THE EXTREME ANTI-VIRUS HA HA !!!
BACK TO LIVE BACK TO REALITY
SICO DE MOEL BERGERWEG 100 CALL 072-114816
Click on this gadget to see a @{" Demo " SYSTEM V-IFF:Extreme} of the Extreme
virus. Push left mouse button to return.